A court or agency acts on injected text
A filing or comment steers a model-assisted clerk toward a wrong ruling or a leaked draft.
AI Risk Atlas Prototype/Demo — Unofficial independent experiment. Not an official xAI product. Scores can be wrong.
Owner · Courts, enterprises, and model vendors
Statement (NASA form)
Given that untrusted text is concatenated into model context in courts, enterprises, and consumer products, and prompt injection remains the leading unfixed LLM failure, there is a possibility of an adversary steering a model that drafts, ranks, or decides inside an institution resulting in corrupted legal filings, leaked data, and decisions that look official but were written by an attacker.
- Condition
- untrusted text is concatenated into model context in courts, enterprises, and consumer products, and prompt injection remains the leading unfixed LLM failure
- Departure
- an adversary steering a model that drafts, ranks, or decides inside an institution
- Impact
- corrupted legal filings, leaked data, and decisions that look official but were written by an attacker
Experimental share of compiled public capital that names this risk. Not a certified residual.
5 public sources · OECD AIM · AIID / ABC · OWASP LLM Top 10 2026
A US court has already sanctioned a filing that hid white-on-white prompt-injection aimed at an AI reader. Practitioners still rank the same bug as number one. Any organisation that lets a model read email, PDFs, or the web has imported this risk.
Simple upstream → via → downstream notes. Not a causal graph. Experimental.
Assumptions · Assumes isolation of untrusted content is still optional in most deployments.
Override is stored on this desk only. It does not make the score official.
Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.
A filing or comment steers a model-assisted clerk toward a wrong ruling or a leaked draft.
A PDF, ticket, or email tells the agent to exfiltrate a warehouse or wire funds.
Poisoned web pages steer every model that trained or retrieved on them.
A US court sanctioned counsel for a white-on-white prompt intended to steer an AI reader of the brief.
Practitioners continue to rank prompt injection as the leading unfixed LLM security problem.
An agent that reads mail and then pays invoices, books travel, or changes ACLs is a prompt-injection terminal.
X posts on the desk that evidence this risk. A signal can contribute to more than one risk.
Court-sanctioned hidden prompt-injection in a filing.
Practitioners still rank injection as the top unfixed failure.
Gray Swan $40M Series A converting into red-team headcount.
Langflow: 12 known-exploited vulns in 2026; 15k+ canary hits. Agent endpoints are the new injection surface.
Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.
Retrieved text cannot change tools, identity, or policy. Treat it as data, never as a program.
Model vendors · expedited 4 weeks · normal 4 months · −1 L · −0 C · −1 U
Wires, filings, ACL changes, and outbound mail require a second channel.
Enterprises and courts · expedited 2 weeks · normal 2 months · −0 L · −2 C · −0 U
Courts and document platforms strip or flag white-on-white, tiny-font, and metadata payloads.
Courts and ECF vendors · expedited 3 weeks · normal 3 months · −1 L · −0 C · −1 U